The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Henrik Plate -- OWASP Top 10 Open Source Risks
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Henrik Plate joins us to discuss the OWASP Top 10 Open Source Risks, a guide highlighting critical security and operational challenges in using open source dependencies. The list includes risks like known vulnerabilities, compromised legitimate packages, name confusion attacks, and unmaintained software, providing developers and organizations a framework to assess and mitigate potential threats. Henrik offers insights on how developers and AppSec professionals can implement the guidelines. Our discussion also includes the need for a dedicated open-source risk list, and the importance of addressing known vulnerabilities, unmaintained projects, immature software, and more. Henrik Plate is the principal security researcher at Endor Labs. He formerly worked for SAP Security Research, where he led the focus topic open source security starting in 2014.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results.
→ Learn more about Security Journey
Connect with Henrik Plate:
→ The OWASP Top 10 Open Source Risks
→ Endor Labs
Mentioned in this episode:
→ The OWASP Top 10 Open Source Risks
→ Endor Labs
→ OpenSSF
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Henrik Plate: OWASP Top 10 Open Source Risks
01:42 We're back on the world of OWASP. We've, we've been away
04:39 Yeah, Henrik, uh, just curious. So, uh, we're talking about the
08:17 The order in this list mean something, or are these all
10:29 Yeah. So if I'm a developer, what, how do I use
12:47 I wonder if we could start to walk through the list
19:43 This, XZ was a more modern example of this, right
22:13 Yeah. And that's, and that's a common problem in the open
24:28 All right, so what is 4
28:28 Okay. So Robert, why don't you, uh, pick one between 8
31:57 All right, Henrik, we have 3 questions that we typically ask
35:01 Uh, the 3rd question is, what's your top book recommendation and
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo